Heap Out-of-Bounds Write Vulnerability in GStreamer by Red Hat
CVE-2026-19387
7.6HIGH
What is CVE-2026-19387?
A heap out-of-bounds write vulnerability was identified in the GStreamer gst-plugins-bad adpcmdec element during the decoding process of IMA/DVI ADPCM audio. This security flaw stems from insufficient validation of the per-block sample count, particularly for multi-channel streams. An attacker could exploit this by delivering a specially crafted WAV file, leading to writes that exceed the bounds of the allocated output buffer. The potential consequences include application crashes, denial of service incidents, memory corruption, and in certain cases, arbitrary code execution when processing untrusted media.
References
CVSS V3.1
Score:
7.6
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Seonwook Kim for reporting this issue.